216.73.216.197

A Deep Dive into Strela Stealer and how it Targets European Countries

· Published 13/04/2025 10:37 · Modified 14/04/2025 12:17

Export JSON

Essential information

Published
13/04/2025 10:37
Modified
14/04/2025 12:17
Tags
2025-03-11 2025-04-13 infostealer locale-verification obfuscation phishing stellar loader strela stealer
Related entities
1 intrusion sets (apt), 15 techniques (mitre), 2 malware, 9 others

Description

, an targeting email clients in specific European countries, has been active since late 2022. It focuses on exfiltrating credentials from Mozilla Thunderbird and Microsoft Outlook. The malware is delivered through campaigns, primarily targeting Spain, Italy, Germany, and Ukraine. Recent attacks involve forwarding legitimate emails with malicious attachments. employs multi-layer and code-flow flattening to complicate analysis. The malware verifies the system's locale before executing, targeting specific German-speaking countries. It searches for email client profile data, encrypts it, and exfiltrates it to a command-and-control server. The infrastructure is linked to Russian bulletproof hosting providers, suggesting potential ties to Russian threat actors.

External references